skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-bullet-chart/Gen Agent Trust Hub
syncfusion-javascript-bullet-chart
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to bind external data to UI components (specifically Bullet Charts) through a
dataSourceproperty, which creates a surface for indirect prompt injection if the ingested data contains malicious instructions. - Ingestion points: Data is ingested via the
dataSourceproperty inSKILL.mdandreferences/data-binding-and-labels.md. - Boundary markers: The skill documentation in
references/title-tooltip-and-interactivity.mdincludes an explicit security warning: "Do not place unsanitized user content inside a tooltip template." - Capability inventory: The skill focuses on data visualization and browser-side data fetching via
fetch(); it does not include instructions for file system writes or privileged command execution. - Sanitization: No built-in sanitization code is provided in the examples, placing the responsibility on the implementing developer as noted in the documentation.
- [EXTERNAL_DOWNLOADS]: The skill references and downloads legitimate library scripts from the vendor's official content delivery network.
- Evidence: Multiple HTML examples in
SKILL.mdandreferences/getting-started.mdreference scripts hosted atcdn.syncfusion.com.
Audit Metadata